Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50663
Total
4071
Critical
15059
High
14768
Medium
CVE ID Severity Score Description Published
CVE-2026-64558 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check the length of the target buffer … Jul 29, 2026
CVE-2026-54727 HIGH 8.2 proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did … Jul 29, 2026
CVE-2026-54693 UNKNOWN — ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone … Jul 29, 2026
CVE-2026-54680 CRITICAL 9.9 Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such … Jul 29, 2026
CVE-2026-54574 HIGH 8.2 proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker … Jul 29, 2026
CVE-2026-52791 UNKNOWN — fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in … Jul 29, 2026
CVE-2026-51992 CRITICAL 9.1 SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. Jul 29, 2026
CVE-2026-20316 MEDIUM 5.3 A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an … Jul 29, 2026
CVE-2026-18257 MEDIUM 5.6 Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered … Jul 29, 2026
CVE-2026-18255 HIGH 7.2 A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member … Jul 29, 2026
CVE-2026-16729 MEDIUM 4.8 undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before … Jul 29, 2026
CVE-2026-15144 HIGH 7.3 @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address … Jul 29, 2026
CVE-2026-13697 HIGH 7.4 undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a … Jul 29, 2026
CVE-2025-60931 HIGH 7.5 An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation … Jul 29, 2026
CVE-2026-67193 MEDIUM 5.3 Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER … Jul 29, 2026
CVE-2026-67192 HIGH 8.1 Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets … Jul 29, 2026
CVE-2026-67191 CRITICAL 9.8 Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap … Jul 29, 2026
CVE-2026-67188 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 29, 2026
CVE-2026-66051 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 29, 2026
CVE-2026-60113 CRITICAL 9.8 AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that … Jul 29, 2026
CVE-2026-60112 CRITICAL 9.8 AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue … Jul 29, 2026
CVE-2026-54735 CRITICAL 10.0 Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate … Jul 29, 2026
CVE-2026-54082 MEDIUM 6.5 veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in … Jul 29, 2026
CVE-2026-54081 UNKNOWN — veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/type1/Type1FontProgram.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a … Jul 29, 2026
CVE-2026-54080 UNKNOWN — veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a … Jul 29, 2026